LiveActive security incident?Get immediate response
CVE archive

May 2016

Browse CVE records published in May 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 764 matching CVEs · Page 3 of 16.

Unknown · CVSS Not scored

CVE-2016-10368: Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior t...

Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the back parameter to the /login URI.

Published May 3, 2017 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2016-10559: selenium-download downloads the latest versions of the selenium standalone server and the chromedriver.

selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

Published May 29, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2016-10627: scala-bin is a binary wrapper for Scala.

scala-bin is a binary wrapper for Scala. scala-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

Published May 29, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2016-10650: ntfserver is a Network Testing Framework Server.

ntfserver is a Network Testing Framework Server. ntfserver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

Published May 29, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2016-10659: poco - The POCO libraries, downloads source file resources used for compilation over HTTP, which leaves it...

poco - The POCO libraries, downloads source file resources used for compilation over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

Published May 29, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2016-10551: waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes...

waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code. A malicious user can input their own SQL statements in waterline-sequel 0.50 that will get executed and have full access to the database.

Published May 29, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2016-10584: dalek-browser-chrome-canary provides Google Chrome bindings for DalekJS.

dalek-browser-chrome-canary provides Google Chrome bindings for DalekJS. dalek-browser-chrome-canary downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

Published May 29, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2016-10547: Nunjucks is a full featured templating engine for JavaScript.

Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape mode. In autoescape mode, all template vars should automatically be escaped. By using an array for the keys, such as `name[]=<script>alert(1)</script>`, it is possible to bypass autoescaping and inject content into the DOM.

Published May 31, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2016-10586: macaca-chromedriver is a Node.js wrapper for the selenium chromedriver.

macaca-chromedriver is a Node.js wrapper for the selenium chromedriver. macaca-chromedriver before 1.0.29 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

Published May 29, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2016-10555: Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could cho...

Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the server. If the server is expecting RSA but is sent HMAC-SHA with RSA's public key, the server will think the public key is actually an HMAC private key. This could be used to forge any data an attacker wants.

Published May 31, 2018 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2016-15031: PHP-Login POST Parameter class.loginscript.php checkLogin sql injection

A vulnerability was found in PHP-Login 1.0. It has been declared as critical. This vulnerability affects the function checkLogin of the file login/scripts/class.loginscript.php of the component POST Parameter Handler. The manipulation of the argument myusername leads to sql injection. The attack can be initiated remotely. Upgrading to version 2.0 is able to address this issue. The patch is identified as 0083ec652786ddbb81335ea20da590df40035679. It is recommended to upgrade the affected component. VDB-228022 is the identifier assigned to this vulnerability.

Published May 6, 2023 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10370: An issue was discovered on OnePlus devices such as the 3T.

An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increases the attack surface, and allows for remote exploitation of other vulnerabilities such as CVE-2017-5948, CVE-2017-8850, and CVE-2017-8851.

Published May 11, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10372: The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execut...

The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and using the NewNTPServer feature.

Published May 16, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10287: An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious applica...

An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33784446. References: QC-CR#1112751.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10288: An elevation of privilege vulnerability in the Qualcomm LED driver could enable a local malicious applicati...

An elevation of privilege vulnerability in the Qualcomm LED driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33863909. References: QC-CR#1109763.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10285: An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious applica...

An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33752702. References: QC-CR#1104899.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10290: An elevation of privilege vulnerability in the Qualcomm shared memory driver could enable a local malicious...

An elevation of privilege vulnerability in the Qualcomm shared memory driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33898330. References: QC-CR#1109782.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10275: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious applicati...

An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-34514954. References: QC-CR#1009111.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10294: An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious applica...

An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33621829. References: QC-CR#1105481.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10286: An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious applica...

An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-35400904. References: QC-CR#1090237.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10293: An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious applica...

An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-33352393. References: QC-CR#1101943.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10283: An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious applica...

An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32094986. References: QC-CR#2002052.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10274: An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious a...

An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-30202412. References: M-ALPS02897901.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10291: An elevation of privilege vulnerability in the Qualcomm Slimbus driver could enable a local malicious appli...

An elevation of privilege vulnerability in the Qualcomm Slimbus driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-34030871. References: QC-CR#986837.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10280: An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious appli...

An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175767. References: M-ALPS02696445.

Published May 12, 2017 · Updated Aug 6, 2024